
Custom Menu Wizard Widget Security & Risk Analysis
wordpress.org/plugins/custom-menu-wizardShow branches or levels of your menu in a widget, or in content using a shortcode, with full customisation.
Is Custom Menu Wizard Widget Safe to Use in 2026?
Generally Safe
Score 85/100Custom Menu Wizard Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-menu-wizard" plugin version 3.3.1 demonstrates a generally good security posture, with no known past vulnerabilities or critical code signals like dangerous functions or unsanitized taint flows. The use of prepared statements for all SQL queries is a significant strength. Furthermore, the plugin appears to have a well-defined attack surface, with all identified entry points (AJAX handlers, shortcodes) appearing to be protected by authentication or capability checks.
However, a notable concern lies in the output escaping. With 215 total outputs and only 20% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully by the application using the plugin's output, could be injected into the page and executed by a user's browser. The presence of only one nonce check and one capability check, while indicating some security measures, also suggests that not all potential injection vectors might be adequately protected, especially in conjunction with the poor output escaping.
In conclusion, while the plugin benefits from a clean vulnerability history and secure database interactions, the widespread lack of proper output escaping presents a substantial security weakness that attackers could exploit for XSS attacks. This requires immediate attention to mitigate potential risks to users and their data.
Key Concerns
- Poor output escaping (20% proper)
- Low number of nonce/capability checks
Custom Menu Wizard Widget Security Vulnerabilities
Custom Menu Wizard Widget Release Timeline
Custom Menu Wizard Widget Code Analysis
SQL Query Safety
Output Escaping
Custom Menu Wizard Widget Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
Custom Menu Wizard Widget Maintenance & Trust
Maintenance Signals
Community Trust
Custom Menu Wizard Widget Alternatives
Bellows Accordion Menu
bellows-accordion-menu
A flexible and robust accordion menu plugin
WP Widget in Navigation
wp-widget-in-navigation
Put your Widget in Navigation easily!
Better Menu Widget
better-menu-widget
Better Menu Widget makes it easy to customize your menu widgets by adding css styles and a heading link.
F12 Floating Menu, sticky menu for WordPress
f12-floating-menu
Easily add unlimited floating/sticky menus to your Website. The F12 Floating Menu comes with an easy-to-use interface, allowing you to have the full c …
The Menu: Custom mobile navigation with icons
the-menu
Create beautiful mobile navigation menus with custom icons, role-based visibility, and extensive style options for your WordPress site.
Custom Menu Wizard Widget Developer Profile
3 plugins · 3K total installs
How We Detect Custom Menu Wizard Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-menu-wizard/custom-menu-wizard.css/wp-content/plugins/custom-menu-wizard/custom-menu-wizard-admin.css/wp-content/plugins/custom-menu-wizard/custom-menu-wizard.js/wp-content/plugins/custom-menu-wizard/custom-menu-wizard-admin.js/wp-content/plugins/custom-menu-wizard/custom-menu-wizard.js/wp-content/plugins/custom-menu-wizard/custom-menu-wizard-admin.jscustom-menu-wizard/custom-menu-wizard.css?ver=custom-menu-wizard/custom-menu-wizard-admin.css?ver=custom-menu-wizard/custom-menu-wizard.js?ver=custom-menu-wizard/custom-menu-wizard-admin.js?ver=HTML / DOM Fingerprints
cmw-menu-item-had-childrencmw-current-item<!-- CMWizard v3.3.1 --><!-- Generated by Custom Menu Wizard -->data-cmw-widget-iddata-cmw-instancecmwizard_options[cmwizard[custom_menu_wizard